Written for risk decisions, not headlines.

Breach, ransomware, advisory and threat intelligence, classified by LiveThreat and refreshed every half hour. Free members receive the digest and set their own topics.

3Last 24 hours
195Last 7 days
2Critical, 7 days
THREAT INTELHighSep 27, 2026

Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools

Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutleshi, 28 years old and a citizen of Kosovo, pleaded guilty last week to building and running the cybercrime marketplace Rydox. The Rydox marketplace has been active since February 2016; it facilitated over 7,600

Security AffairsLiveThreat brief →
BREACHHighSep 27, 2026

Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Know what was tested before your SAP ECC migration goes live In this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that choice may cost, why fear of disruption stalls projects more often …

Help Net SecurityLiveThreat brief →
THREAT INTELHighSep 26, 2026

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

The Hacker NewsLiveThreat brief →
THREAT INTELHighSep 26, 2026

Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem

Exploit.in data shows how a 2005 cybercrime forum helped shape today’s ransomware ecosystem, with users and practices surviving for decades. Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers inside it tell a story about Russian cybercrime that enforcement

Security AffairsLiveThreat brief →
THREAT INTELHighSep 26, 2026

Zero Trust for AI Agents Starts With Fixing Zero Visibility

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to

The Hacker NewsLiveThreat brief →
ADVISORYHighSep 26, 2026

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief

The Hacker NewsLiveThreat brief →
ADVISORYInformationalSep 26, 2026

CISA Unveils US Midterm Election Security Plan

CISA Taps Regional Directors as Election Advisers Amid Unspent EI-ISAC Funds The U.S. Cybersecurity and Infrastructure Security Agency released a 2026 election security plan offering state and local officials free threat sharing, scanning and advisory support ahead of the midterms, as lawmakers say funding Congress set aside for an election threat-sharing hub remains unspent.

DataBreachTodayLiveThreat brief →
THREAT INTELMediumSep 26, 2026

7-Year, $11.6B Anthropic Deal Drives Akamai Cloud Buildout

CPU-Based Agreement With Anthropic Will Require Major Cloud Capacity From Akamai San Francisco-based frontier AI lab Anthropic committed $11.6 billion over seven years to Akamai cloud infrastructure for CPU-based AI workloads, giving Boston-area Akamai its largest contract ever and triggering a $5.5 billion capacity buildout ahead of revenue beginning in 2027.

DataBreachTodayLiveThreat brief →
THREAT INTELHighSep 26, 2026

US Appeals Court Backs Pentagon Blacklisting of Anthropic

D.C. Circuit says Claude’s built-in restrictions can qualify as a supply chain risk A federal three judge panel gave the U.S. Department of Defense the go-ahead to continue blacklisting Anthropic, a setback in the artificial intelligence giant's bid to take on the Trump administration in court. The ruling may dissuade companies from working with Anthropic.

DataBreachTodayLiveThreat brief →
ADVISORYHighSep 26, 2026

CISA And FBI Warn OT Operators About Third-Party Hacking

An Intrusion Last Year May Have Provided Hackers With a Roadmap for OT Cyberattacks U.S. authorities are warning companies that use operational technology to take care when granting online access to third-party integrators or consultants, warning that foreign hackers are actively using such connections as a vector for cyberattacks.

DataBreachTodayLiveThreat brief →
ADVISORYHighSep 25, 2026

U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-65660 is a code-injection vulnerability in Microsoft SharePoint Server that allows an authenticated, low-privileged attacker to execute arbitrary

Security AffairsLiveThreat brief →
Page 1 of 34 Older →

Intelligence provided by LiveThreat, a product of a founding sponsor of the association. Each brief links to LiveThreat's analysis and the original source. RSS: Breach & Ransomware Watch Advisories & Threat Intel

Practitioner briefings

Written by the association: what the week's intelligence means for the controls you run.

Advisory · high

Reading a vendor's breach notice for what it does not say

A practitioner checklist for turning a supplier notification into an evidence request and a monitoring change.

TPR CYB
Read
Briefing · medium

Where AI inventory efforts stall, and the control that unblocks them

Findings from practitioner roundtables on AI governance programs in their first year.

AIG GRC
Read
Research

Evidence reuse across customer diligence and audit

How practitioners are organizing one evidence base to serve buyers and auditors at the same time.

GRC TRS
Read
Advisory · medium

Global Privacy Control signals and state opt-out obligations

What a site must do when it sees a GPC signal, and how to evidence it.

PRV
Read

Get the digest

No membership required. Confirm by email; unsubscribe in one click.